Infostealers: One Infection, Every Password
One cheap malware infection can expose every saved login an employee has. How infostealers feed the credential economy — and how to cut off the supply.

In the spring of 2024, attackers walked into the Snowflake environments of roughly 165 organizations and extorted some of the biggest names in retail, telecom, and entertainment. There was no zero-day and no breach of Snowflake itself. Mandiant's investigation found that the majority of the credentials used had come from historical infostealer infections — some dating as far back as 2020 — many harvested from contractor machines that were also used for gaming and pirated software, protecting accounts that had no multi-factor authentication. Years-old malware on personal laptops, plus passwords nobody rotated, equaled one of the most consequential attack campaigns of the decade.
That is the infostealer economy in miniature. A cheap, disposable piece of malware runs for seconds on one machine, sweeps up every saved credential it can find, and the resulting "log" circulates in criminal markets for years — until someone finally checks whether your VPN password still works. This guide explains how that pipeline operates, why unmanaged devices are its main intake, and how to cut off the supply from the human layer up.
What an infostealer actually takes
An infostealer is not designed to persist, encrypt, or spy over months. It is a smash-and-grab tool with one job: harvest everything on a device that grants access, exfiltrate it in under a minute, and often delete itself. A typical log contains:
- Saved browser passwords — every account the victim ever let the browser remember, personal and corporate alike
- Session cookies and authentication tokens — which allow session hijacking: stepping into an account after MFA has been satisfied, with no login prompt at all
- Autofill data — names, addresses, phone numbers, payment card details
- Crypto wallets, VPN configurations, FTP and email client credentials
- Files matching patterns like
passwords.txtorrecovery codes
The scale is industrial. IBM's X-Force 2025 Threat Intelligence Index recorded an 84% year-over-year increase in emails delivering infostealers in 2024, with early 2025 data pointing to a 180% jump against 2023 — and found the top five stealer families advertised in more than eight million dark web listings, each of which can contain hundreds of credentials. Nearly one in three incidents X-Force observed in 2024 ended in credential theft.
The supply chain: from a $250 subscription to your VPN
Infostealers are the clearest example of cybercrime specialization. The developer, the distributor, the log marketplace, and the final attacker are usually four different parties — and the entry price is trivial.
Lumma Stealer, the most prolific family of the past few years, ran as a polished malware-as-a-service business. When Microsoft's Digital Crimes Unit, the U.S. Department of Justice, Europol, and Japan's Cybercrime Control Center dismantled its infrastructure in May 2025, the court filings read like a SaaS teardown: subscription tiers from $250 to $20,000, roughly 400 active criminal customers, distribution through spear-phishing and malvertising that impersonated trusted brands. In just the two months before the takedown, Microsoft identified over 394,000 infected Windows devices worldwide, and some 2,300 malicious domains were seized. Europol called Lumma "the world's largest infostealer" — and it was also the most common payload delivered by ClickFix fake-fix attacks, where the victim is talked into running the infection command personally.
Downstream, the logs become inventory. Marketplaces index them by corporate domain, so an initial access broker can search for yourcompany.com and buy a working SSO or VPN credential for a few dollars — months or years after the infection. From there the path leads wherever the buyer's business model points: ransomware deployment, credential stuffing across your SaaS estate, business email compromise, or a Snowflake-style data heist.
| Signal | Figure | Source |
|---|---|---|
| Emails delivering infostealers, 2024 vs 2023 | +84% | IBM X-Force 2025 |
| Dark web ads for top five stealer families | 8M+ listings | IBM X-Force 2025 |
| Devices infected with Lumma, 16 Mar–16 May 2025 | 394,000+ | Microsoft DCU |
| Infostealer-compromised systems with corporate logins that were non-managed personal devices | 46% | Verizon 2025 DBIR |
| Snowflake customer accounts attacked via previously exposed credentials | ~80% | Mandiant |
Why personal devices are the blind spot
The most important number in the table is Verizon's. In its 2025 Data Breach Investigations Report, Verizon analyzed infostealer logs and found that 30% of compromised systems were enterprise-licensed devices — but 46% of the compromised systems that contained corporate logins were non-managed personal devices. Nearly half of the corporate credentials circulating in stealer logs were never touched by your EDR, your patching, or your policies.
The mechanism is mundane. An employee signs in to webmail from a home PC. A contractor keeps client VPN credentials in the same browser profile they use for torrenting. Browser sync helpfully copies a work password vault onto a gaming laptop. None of this is malicious; all of it extends the corporate attack surface onto machines the security team has never seen — the same boundary erosion that drives remote-work and BYOD risk generally.
An infostealer does not breach your perimeter. It waits for a copy of your perimeter to walk onto a machine you do not control — and then it reads the passwords off the shelf.
This is why infostealers are best understood as a human risk problem with a malware component, rather than the reverse. The infection is almost always a human decision — install the "free" version, run the fake update, paste the fix command. Where the credentials live is a human decision. And whether a years-old password still opens your front door is an organizational decision.
How to cut off the supply
You cannot stop criminals from selling logs. You can make your organization's entries in them scarce, stale, and worthless. Work the problem at four layers:
1. Shrink what a stealer can reach. Keep corporate credentials off unmanaged devices: enforce device-based conditional access so unknown machines cannot complete a corporate sign-in, separate contractor access with dedicated managed profiles or virtual desktops, and restrict personal browser-profile sync on work machines. Where saved browser passwords are policy, point them at a managed enterprise vault instead.
2. Devalue what gets stolen. Passkeys and hardware-bound FIDO2 credentials do not yield a reusable secret for a stealer to grab. Short session lifetimes and token revocation shrink the value of stolen cookies. Universal MFA — the control whose absence turned the Snowflake credentials into breaches — plus rotation on any credential that touches critical systems means a 2020-vintage log entry opens nothing in 2026.
3. Watch the market. Breached-credential monitoring that alerts when your domain appears in fresh logs turns the criminal supply chain into your telemetry. Treat every hit as an incident: reset, revoke sessions, examine the source device, and check sign-in history for use.
4. Train for the delivery layer. Cracked software, fake updates, malvertising, and fix-it-yourself prompts are social engineering, and they respond to the same treatment as phishing: teach the patterns, then rehearse them with realistic simulations that include fake-update and paste-and-run lures, not just email links. Feed the results — who runs unknown installers, which teams sign in from personal devices — into a human risk score so the exposure is measured per team rather than guessed. That behavioral layer is the core of human risk management: the infection point, the credential sprawl, and the reporting reflex are all human behaviors, and all of them can be measured and improved.
The takeaway
The Lumma takedown was a genuine win, but the model it proved — $250 subscriptions, four hundred customers, hundreds of thousands of infections in two months — does not die with one brand. Logs already harvested will keep resurfacing for years, exactly as the 2020 credentials did in the Snowflake campaign. The organizations that stay off the victim lists will be the ones that assume some employee credentials are already for sale, make those credentials worthless on arrival, and treat every "free download" reflex as a measurable, trainable human risk.
Frequently asked questions
How do infostealer infections usually start?
Almost always with a human decision, not an exploit. The classic lures are cracked or 'free' software, fake browser and driver updates, malicious ads, game cheats, phishing attachments, and ClickFix-style fake fix instructions that talk the user into running a command themselves. Microsoft's takedown filings describe Lumma spreading through spear-phishing and malvertising while impersonating trusted brands. Because delivery depends on persuasion, awareness training and simulation belong in the defense alongside endpoint controls.
Can an infostealer bypass multi-factor authentication?
Effectively yes, by stealing the session rather than the login. Stealers grab browser cookies and authentication tokens along with passwords, and a fresh session token lets an attacker step into an account after MFA has already been completed — no prompt, no push notification. That is why short session lifetimes, token binding, and phishing-resistant methods like passkeys matter: they shrink or remove the value of what the stealer exfiltrates.
Why are personal and contractor devices such a big infostealer risk?
Because they carry corporate logins without corporate controls. Verizon's 2025 DBIR found that 46% of infostealer-compromised systems holding corporate credentials were non-managed personal devices. Mandiant's investigation of the Snowflake customer attacks found the same pattern: contractor machines used for gaming and pirated downloads were infected years earlier, and the harvested credentials — some dating to 2020 — still worked because they had never been rotated and lacked MFA.
What should a company do if its credentials appear in an infostealer log?
Treat it as an active incident, not a curiosity. Reset the exposed passwords, revoke and reissue sessions and tokens for the affected identities, check the source device — if it is unmanaged, assume everything typed or saved on it is exposed — and review sign-in logs for use of the credentials. Then feed the lesson back into the program: which lure worked, which policy gap let a work login live on that machine, and which team needs targeted training next.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo